Ubuntu 6581 Published by

A CKEditor security update has been released for Ubuntu Linux 18.04 LTS, 20.04 LTS, and 21.10.



==========================================================================
Ubuntu Security Notice USN-5340-1
March 22, 2022

ckeditor vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in CKEditor.

Software Description:
- ckeditor: text editor which can be embedded into web pages

Details:

Kyaw Min Thein discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue
to execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS. (CVE-2018-9861)

Micha Bentkowski discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-9281)

Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. This issue only affects
Ubuntu 21.10. (CVE-2021-32808)

Anton Subbotin discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
inject arbitrary code. (CVE-2021-32809)

Or Sahar discovered that CKEditor incorrectly handled certain
inputs. An attacker could possibly use this issue to execute
arbitrary code. This issue only affects
Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-33829)

Mika Kulmala discovered that CKEditor incorrectly handled
certain inputs. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2021-37695)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
ckeditor 4.16.0+dfsg-2ubuntu0.1

Ubuntu 20.04 LTS:
ckeditor 4.12.1+dfsg-1ubuntu0.1

Ubuntu 18.04 LTS:
ckeditor 4.5.7+dfsg-2ubuntu0.18.04.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5340-1
CVE-2018-9861, CVE-2020-9281, CVE-2021-32808, CVE-2021-32809,
CVE-2021-33829, CVE-2021-37695

Package Information:
https://launchpad.net/ubuntu/+source/ckeditor/4.16.0+dfsg-2ubuntu0.1
https://launchpad.net/ubuntu/+source/ckeditor/4.12.1+dfsg-1ubuntu0.1
https://launchpad.net/ubuntu/+source/ckeditor/4.5.7+dfsg-2ubuntu0.18.04.1